USENIX Security2025Top-tier venue
No Way to Sign Out? Unpacking Non-Compliance with Google Play's App Account Deletion Requirements
Jingwen Yan, Song Liao, Jin Ma, Mohammed Aldeen, Salish Kumar, Long Cheng
Abstract
Despite the significant convenience mobile apps bring to our daily lives, the collection and use of personal information by these apps remain a major concern, particularly regarding how such data is handled after users sign out. To align with regulations like the General Data Protection Regulation (GDPR) that have included specific provisions granting individuals the right to request data deletion, mobile app stores, such as Google Play, have introduced new account deletion requirements that require apps to provide proper account deletion methods. In this work, we conducted the first study on investigating non-compliance issues with Google Play's app account deletion requirements. Starting with a pilot study of the top 50 apps on Google Play, we identified potential issues related to account deletion and defined three main categories of issues: link issues, content issues, and functionality issues. Based on these findings, we developed a tool named DELETETRACKER to automatically collect account deletion-related information from Google Play and semi-automatically identify non-compliance issues regarding account deletion. Using DELETETRACKER, we analyzed 863 Google Play apps' account deletion information. Among the 494 apps with accessible account deletion links, DELETETRACKER found only 8.5% of apps to provide both in-app path and web-based account deletion methods, which fully comply with Google Play's account deletion requirements. 64.6% of apps offer only one account deletion method. We also found 12 apps that failed to delete user accounts. We have reported our findings to Google through the vulnerability reporting process. Following our disclosure, Google acknowledged the reported issue and assigned it a Medium (S2) severity level.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on6
- "It's a scavenger hunt": Usability of Websites' Opt-Out and Data Deletion ChoicesHana Habib, Sarah Pearman, Jiamin Wang, Yixin Zou et al.CHI 2020 · 113 citations
- Understanding Account Deletion and Relevant Dark Patterns on Social MediaBrennan Schaffner, Neha A. Lingareddy, Marshini ChettyCSCW 2022 · 66 citations
- SkillScanner: Detecting Policy-Violating Voice Applications Through Static Analysis at the Development PhaseSong Liao, Long Cheng, Haipeng Cai, Linke Guo et al.CCS 2023 · 7 citations
- Scraping Sticky Leftovers: App User Information Left on Servers After Account DeletionPreethi Santhanam, Hoang Dang, Zhiyong Shan, Iulian NeamtiuS&P 2022 · 5 citations
- End-Users Know Best: Identifying Undesired Behavior of Alexa Skills Through User Review AnalysisMohammed Aldeen, Jeffrey Young, Song Liao, Tsu-Yao Chang et al.UbiComp 2024 · 4 citations
Related papers
- Freely Given Consent?: Studying Consent Notice of Third-Party Tracking and Its Violations of GDPR in Android AppsTrung Tin Nguyen, Michael Backes, Ben StockCCS 2022 · 32 citations
- How Are Your Zombie Accounts? Understanding Users' Practices and Expectations on Mobile App Account DeletionYijing Liu, Yan Jia, Qingyin Tan, Zheli Liu et al.USENIX Security 2022
- PolicyChecker: Analyzing the GDPR Completeness of Mobile Apps' Privacy PoliciesAnhao Xiang, Weiping Pei, Chuan YueCCS 2023 · 24 citations
- Is It a Trap? A Large-scale Empirical Study And Comprehensive Assessment of Online Automated Privacy Policy Generators for Mobile AppsShidong Pan, Dawen Zhang, Mark Staples, Zhenchang Xing et al.USENIX Security 2024 · 18 citations
- Analyzing User Perspectives on Mobile App Privacy at ScalePreksha Nema, Pauline Anthonysamy, Nina Taft, Sai Teja PeddintiICSE 2022 · 50 citations
